[ANNOUNCE] Apache SkyWalking 9.6.0 released

2023-09-05 Thread Sheng Wu
Hi all, Apache SkyWalking Team is glad to announce the first release of Apache SkyWalking 9.6.0. SkyWalking: APM (application performance monitor) tool for distributed systems, especially designed for microservices, cloud native and container-based (Docker, Kubernetes, Mesos) architectures. This

[ANNOUNCEMENT] Apache Commons DBCP 2.10.0

2023-09-05 Thread Gary Gregory
The Apache Commons DBCP team is pleased to announce the release of Apache Commons DBCP 2.10.0. Apache Commons DBCP software implements Database Connection Pooling. This is a minor release, including bug fixes and enhancements: https://commons.apache.org/proper/commons-dbcp/changes-report.html#a2.

[ANN] Apache Struts 6.3.0

2023-09-05 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Apache Struts version 6.3.0 is available as a “General Availability” release. The GA designation is our highest quality grade. The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framewor

CVE-2023-40743: Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService

2023-09-05 Thread Arnout Engelen
Severity: low Affected versions: - Apache Axis through 1.3 Description: ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms